2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24924 | MEDIUM | 6.1 | 0.8% | Dec 6, 2021 | The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in... |
| CVE-2021-24917 | HIGH | 7.5 | 71.5% | Dec 6, 2021 | The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random... |
| CVE-2021-24914 | HIGH | 8 | 0.5% | Dec 6, 2021 | The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and... |
| CVE-2021-24866 | CRITICAL | 9.8 | 1.6% | Dec 6, 2021 | The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before ... |
| CVE-2021-24759 | MEDIUM | 5.4 | 0.6% | Dec 6, 2021 | The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, wh... |
| CVE-2021-24718 | MEDIUM | 4.8 | 0.6% | Dec 6, 2021 | The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its sett... |
| CVE-2021-24714 | MEDIUM | 4.8 | 0.6% | Dec 6, 2021 | The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier... |
| CVE-2021-43471 | HIGH | 7.5 | 1.4% | Dec 6, 2021 | In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can rem... |
| CVE-2021-4069 | HIGH | 7.8 | 1.3% | Dec 6, 2021 | vim is vulnerable to Use After Free |
| CVE-2021-43469 | HIGH | 8.8 | 2.3% | Dec 6, 2021 | VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component. |
| CVE-2021-43044 | CRITICAL | 9.8 | 1.9% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak d... |
| CVE-2021-43043 | MEDIUM | 6.5 | 1.4% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files s... |
| CVE-2021-43042 | CRITICAL | 9.8 | 2.9% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer... |
| CVE-2021-43041 | HIGH | 8.8 | 2.3% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format... |
| CVE-2021-43040 | HIGH | 8.8 | 1.8% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leverage... |
| CVE-2021-43039 | MEDIUM | 6.5 | 1.2% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anony... |
| CVE-2021-43038 | HIGH | 8.8 | 2.2% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by... |
| CVE-2021-43037 | HIGH | 7.8 | 0.5% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable t... |
| CVE-2021-43036 | CRITICAL | 9.8 | 1.9% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest accou... |
| CVE-2021-43035 | CRITICAL | 9.8 | 3.3% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabil... |
| CVE-2021-43034 | HIGH | 7.8 | 0.4% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to... |
| CVE-2021-43033 | CRITICAL | 9.8 | 6.0% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon w... |
| CVE-2021-44048 | HIGH | 7.8 | 0.8% | Dec 5, 2021 | An out-of-bounds write vulnerability exists when reading a TIF file using Open Design Alliance (ODA) Drawings Explorer b... |
| CVE-2021-44047 | HIGH | 7.8 | 0.9% | Dec 5, 2021 | A use-after-free vulnerability exists when reading a DWF/DWFX file using Open Design Alliance Drawings SDK before 2022.1... |
| CVE-2021-44046 | HIGH | 7.8 | 0.8% | Dec 5, 2021 | An out-of-bounds write vulnerability exists when reading U3D files in Open Design Alliance PRC SDK before 2022.11. An un... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now